Anthropic introduced the Life Sciences Verification Program (LSVP), a beta program that allows life sciences professionals to use its Mythos, Opus, and Sonnet models with safeguards tailored to biological work. The initiative aims to support tasks such as drug discovery, clinical research, and manufacturing without removing safety controls.
The proposal starts with a difficult tension: the same AI that can help develop a vaccine could also be used to investigate how to make a pathogen more dangerous. How do you allow legitimate work without opening an easy door to abuse? Anthropic is trying to answer that question through prior verification, continuous monitoring, and shared responsibility.
Two Access Levels for Biological Work
The program is initially aimed at teams and institutions, from academic laboratories and startups to pharmaceutical companies. Anthropic says it has already brought in dozens of organizations through an early-access program and will now open applications to a broader community.
To participate, each organization must demonstrate its research credentials, safety standards, and ethical oversight mechanisms. After verification, it can request one of two types of permissions:
- Standard Use: designed for most research and development activities in biology. It can cover entire teams and is renewed annually.
- High-risk Use: intended for specific projects with a higher potential for misuse. It requires an additional review, is granted for a single project, and must be renewed every six months.
Access can be used in products such as Claude Science, Claude.ai, Claude Code, and the API, although availability depends on the account type and environment. Standard Use permissions already apply to Mythos 5.1, Opus 5, and Sonnet 5, as well as future models Anthropic adds to the program.
What Changes Compared with General Access
The general-use versions of the models may block certain biology-related requests. LSVP uses refined classifiers that allow a broader range of scientific tasks, including basic research, product development, supply chain operations, manufacturing, clinical trials, quality control, regulatory affairs, and investment activities.
High-risk Use goes further: it removes the safeguards that block life sciences requests within the authorized scope. That does not mean the team has unlimited freedom. Access is tied to a specific project and remains subject to other controls, including cybersecurity classifiers.
For now, high-risk permissions are available for Claude Opus 5 and Claude Sonnet 5. Anthropic says it is working with the United States Government to expand that access to Mythos, but at launch it will remain limited to a small group of entities with an additional review.
Security Relies on the Organization
Anthropic identifies three main risk scenarios:
- Access compromise: malware or account theft that allows someone else to use the account.
- Insider threats: employees who act maliciously, are coerced, or misuse their access.
- Agent misuse: autonomous systems that unexpectedly take dangerous actions, especially during extended tasks or when multiple agents are working together.
To reduce these risks, each organization must describe which uses it considers safe in its application. The description should be general, similar to a job posting, and must not include confidential information or intellectual property.
Anthropic then compares actual use with the declared scope. If it detects unauthorized activity, it can alert the organization’s administrators so they can investigate and respond within the agreed timelines.
The program’s central idea is simple: Anthropic expands access, but institutions also take an active share of the oversight.
Fewer Real-Time Blocks, More Retrospective Analysis
In its general-access models, Anthropic typically blocks a potentially dangerous request the moment it occurs. With LSVP, the company will move part of that protection to an offline monitoring system.
This makes it possible to analyze patterns spread across multiple requests and sessions. That matters because malicious use may look harmless when viewed in isolation but reveal a risk when the full sequence is reviewed.
The trade-off is data retention. Anthropic requires information associated with activity flagged for review to be kept for 30 days. The company says this data will be compartmentalized, will not be used to train models, and will not be accessible to its internal life sciences research teams.
The program could also integrate with Enterprise Frontier Safeguards, Anthropic’s set of enterprise protection tools, for organizations that meet the requirements.
Current Availability and Limitations
LSVP is available through Anthropic’s own console for using the API, as well as through the Claude Enterprise and Team plans. For now, it is not enabled for individual plans or third-party platforms, although the company plans to expand access.
During the beta, the program is also unavailable to organizations with BAA agreements. As a result, customers working with protected health information will need to use separate organizations that do not have BAA or HIPAA enabled.
In the API and Claude Science, users can switch between permissions natively. In Claude.ai and Claude Code, a preselected default permission will initially be applied, except when Claude Code uses API authentication.
Anthropic expects to bring in hundreds of organizations during the first week and scale the program in the following weeks. Companies that have expressed their support include Xaira, Edison, and Manifold Bio, all focused on applying artificial intelligence to biological research and drug development.
The decision reflects a trend we will see more often: AI is not released in the same way for every context. A general chatbot may need strict limits, while a verified laboratory requires more flexible tools to move legitimate research forward. The challenge will be showing that institutional oversight works as well as the technology promises.
Original Source
https://www.anthropic.com/news/life-sciences-verification-program
